An Intrusion and Fault Tolerant Forensic Storage for a SIEM System | IEEE Conference Publication | IEEE Xplore

An Intrusion and Fault Tolerant Forensic Storage for a SIEM System


Abstract:

Current Security Information and Events Management (SIEM) solutions lack a data storage facility which is secure enough - i.e. stored events related to security incidents...Show More

Abstract:

Current Security Information and Events Management (SIEM) solutions lack a data storage facility which is secure enough - i.e. stored events related to security incidents cannot be forged and are always available - that it can be used for forensic purposes. Forensic storage used by current SIEM solutions uses traditional RSA algorithm to sign the security events. In this paper we have analyzed the limits of current forensic storages, and we have proposed an architecture for forensic storage, implementing a threshold-based variant of the RSA algorithm, that outperforms state of the art SIEM solutions in terms of intrusion- and fault-tolerance. We show by experiments that our forensic storage works correctly even in the presence of cyber-attacks, although with a performance penalty. We also conduct an experimental campaign to evaluate the performance cost of the proposed scheme as a function of the threshold.
Date of Conference: 25-29 November 2012
Date Added to IEEE Xplore: 10 January 2013
ISBN Information:
Conference Location: Sorrento, Italy

Contact IEEE to Subscribe

References

References is not available for this document.